vpnc disconnects after 57 minutes during rekey

Asked by spinylumpsucker

This problem is reproducable on vpnc_0.5.3r512-2ubuntu1_amd64.deb, but may exist on any 0.5.3r512 release.

We are connecting to a Cisco ASA 5500 series VPN controlled.

Connections behave correctly until approximately 57 minutes after initiation.
The failure seems to occur during a n attempt to "rekey" with the controller.
From the Cisco controller logs:

Sep 17 11:03:44 vpn-nj-int %ASA-5-713041: Username = test, IP = 74.94.59.17, IKE Initiator: Rekeying Phase 1, Intf outside, IKE Peer 74.94.59.17 local Proxy Address 0.0.0.0, remote Proxy Address 0.0.0.0, Crypto map (N/A)
Sep 17 11:04:16 vpn-nj-int %ASA-5-713259: Group = research, Username = test, IP = 74.94.59.17, Session is being torn down. Reason: Lost Service
Sep 17 11:04:16 vpn-nj-int %ASA-4-113019: Group = research, Username = test, IP = 200.214.170.116, Session disconnected. Session Type: IPsecOverNatT, Duration: 0h
:57m:36s, Bytes xmt: 674349, Bytes rcv: 574596, Reason: Lost Service

This appears to be a reintroduction of an earlier bug.

Does anyone have a patch or know of a work around?

Question information

Language:
English Edit question
Status:
Answered
For:
Ubuntu vpnc Edit question
Assignee:
No assignee Edit question
Last query:
Last reply:
Revision history for this message
actionparsnip (andrew-woodhead666) said :
#1

Have you tried connecting to the VPN using network manager?

Revision history for this message
spinylumpsucker (bill-nec-labs) said :
#2

Yes using the network-manager-vpnc package.
Note that this issue seems related to https://bugs.launchpad.net/ubuntu/+source/vpnc/+bug/479632.

Revision history for this message
Ralph Schmieder (ralph-schmieder) said :
#3

I've written a patch that addresses this problem (plus some other enhancements). Please see

http://lists.unix-ag.uni-kl.de/pipermail/vpnc-devel/2015-June/004163.html

for the patch and some explanation.

https://bugs.launchpad.net/ubuntu/+source/vpnc/+bug/479632 mentions that this is fixed ('this bug is closed, and the fix has been in Ubuntu since vpnc/0.5.3r449-2.1 (likely 11.04)'). However, the phase 1 rekey was definitely missing.

Can you help with this problem?

Provide an answer of your own, or ask spinylumpsucker for more information if necessary.

To post a message you must log in.